Junglewise Threat Intelligence

CVE-2025-71165: Typesetter CMS reflected XSS in Tools Status administrative interface

CVE-2025-71165 · Severity: medium · CVSS 5.4 · Published 2026-01-14

Technologies: Typesetter CMS, Typesettercms Typesetter. Vendors: Typesetter, Typesettercms.

Executive brief

Typesetter CMS, an open-source content management system, contains a security flaw in its administrative dashboard. An attacker can trick a logged-in administrator into clicking a malicious link, allowing the attacker to run unauthorized scripts in the administrator's browser. This could lead to the theft of session cookies, unauthorized changes to the website, or access to sensitive administrative data.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Typesetter CMS versions up to 5.1. The vulnerability is located in the 'Tools Status' functionality within the administrative interface, specifically in the 'include/admin/Tools/Status.php' file. The 'path' parameter is reflected into the HTML response without proper output encoding. An authenticated attacker can exploit this by supplying crafted input containing HTML or JavaScript. Successful exploitation requires the victim (an authenticated user) to interact with a malicious link, resulting in arbitrary script execution in the context of their browser session. As of the advisory date, the project appears to be unmaintained, and no official patch has been confirmed.

Affected products

  • Typesetter Typesetter CMS <= 5.1

Timeline

  • 2025-03-09: disclosed: Issue reported on GitHub repository
  • 2026-01-14: advisory: NVD/VulnCheck advisory published

References

Related threats